Medium severity5.3NVD Advisory· Published Nov 16, 2018· Updated Jun 17, 2026
CVE-2018-9071
CVE-2018-9071
Description
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.
Affected products
3<2.0.0+ 1 more
- (no CPE)range: <2.0.0
- (no CPE)range: unspecified
- cpe:2.3:o:lenovo:chassis_management_module_firmware:*:*:*:*:*:*:*:*Range: <2.0.0
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/solutions/LEN-23806nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.